| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q4gh-4ffp-5cg8 | MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 18 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magicmirrororg
Magicmirrororg magicmirror |
|
| Vendors & Products |
Magicmirrororg
Magicmirrororg magicmirror |
Tue, 18 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder in js/server_functions.js before invoking socketNotificationReceived. A client connected to a loaded module namespace can submit a SECRET_API_KEY placeholder, causing the server to replace it with the corresponding process environment value. The default weather helper accepts INIT_WEATHER, copies the attacker-controlled instanceId, and returns it in WEATHER_ERROR, providing an echo path for the expanded secret. This reverses the intended one-way redaction boundary and can disclose API tokens, credentials, or service keys stored in SECRET_ variables. This issue is fixed in version 2.37.0. | |
| Title | MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T17:56:32.044Z
Reserved: 2026-07-17T14:11:15.483Z
Link: CVE-2026-63640
Updated: 2026-08-18T17:56:10.315Z
Status : Received
Published: 2026-08-18T18:19:11.800
Modified: 2026-08-18T18:19:11.800
Link: CVE-2026-63640
No data.
OpenCVE Enrichment
Updated: 2026-08-18T18:45:03Z
Github GHSA